ENTERPRISE INTERNAL CONTROL & STANDARD OPERATING PROCEDURE MANUAL
- Nhung Nguyen
- Jun 27
- 12 min read
Document Code: CO-ICM-2026-V1
Target Compliance Frameworks: COSO 2013, PCAOB AS 2201, SOX Section 404, IFRS / US GAAP
Scope: Global Operations & Subsidiary Frameworks
SECTION I: MANUAL ARCHITECTURE & COMPLIANCE METHODOLOGY
1. The COSO 2013 Control Environment
This manual enforces the five integrated components of the COSO 2013 Internal Control-Integrated Framework:
Control Environment: Foundation for all other components, driven by "Tone at the Top," ethical values, and organizational structure.
Risk Assessment: Dynamic process for identifying and analyzing risks to achieving objectives.
Control Activities: Policies and procedures helping ensure management directives to mitigate risks are carried out.
Information & Communication: Identification, capture, and exchange of information in a form and timeframe enabling people to carry out responsibilities.
Monitoring Activities: Ongoing evaluations, separate evaluations, or some combination of the two used to ascertain whether each of the five components of internal control is present and functioning.
2. Control Classification Matrix
Every control documented in this manual must be cataloged using four primary dimensional attributes:

Execution Mode:
Automated (A): System-enforced controls (e.g., three-way match tolerances in SAP).
Semi-Automated (SA): System-generated report reviewed manually (e.g., reviewing an ERP-generated exception report).
Manual (M): Performed completely outside systems (e.g., physical stock counts).
Control Objective:
Preventative (P): Designed to stop errors or fraud before they occur.
Detective (D): Designed to identify and correct errors or fraud after occurrence.
Significance:
Key Control (KC): Crucial to preventing or detecting material misstatements in financial reports. Tested directly by auditors.
Non-Key Control (NK): Enhances operational efficiency or administrative accuracy but is not primary to SOX/financial assertion mitigation.
Financial Assertions Addressed:
C - Completeness
E - Existence / Occurrence
A - Accuracy / Valuation
R - Rights & Obligations
P - Presentation & Disclosure
SECTION II: GRANULAR CORE BUSINESS CYCLES
1. Sales and Cash Collection Cycle (Revenue & Receivables)
1.1 End-to-End Procedural Flow
Lead & Sales Proposal: Opportunities are qualified in CRM. Proposals are created using system-locked price libraries.
MOU & Credit Evaluation: Prior to legal binding, a credit review is initiated via the credit team.
Contract Execution & Master Data Setup: Legal signs off on deviated terms. Customer master data is locked in the ERP.
Order Processing: Sales Order (SO) generated against standard SKUs.
Fulfillment & Delivery: Warehouse picks, packs, and ships. Delivery Order (DO) or Bill of Lading (BOL) is executed.
Billing & Invoice Generation: Revenue accounting issues a fiscal invoice matching actual shipped quantities.
Cash Application & AR Reconciliation: Remittance received via lockbox/wire. Applied to open balances; monthly age-analysis performed.
1.2 Process Flow Diagram
[CRM Proposal] ──> [Credit Evaluation] ──> [Contract Signed] ──> [Sales Order Approved]
│
[AR Reconciliation] <── [Cash Receipt] <── [Invoice Issued] <── [Fulfillment & DO]
1.3 Risk & Control Matrix (RCM)
Control ID | Process Step | Risk Description (What Could Go Wrong - WCGW) | Financial Assertion | Control Activity Description | Type / Mode | Owner | Evidence Artifact |
REV-KC-01 | Credit Review | Orders processed for high-risk customers, causing material uncollectible bad debts. | A | ERP system automatically blocks sales orders if a customer's balance exceeds approved credit limits. Credit limit overrides require written approval from the CFO. | P / A | Credit Manager | System Credit Exception Log & Sign-off |
REV-KC-02 | Fulfillment | Shipments made to unapproved entities or diverted without valid orders, causing revenue misstatement. | E | Shipping module will not generate a packing list or gate pass unless tied to an approved, system-validated Sales Order. | P / A | Logistics Lead | Executed Bill of Lading matched to SO |
REV-KC-03 | Invoicing | Invoices issued for incorrect quantities or pricing, leading to top-line misstatement. | A,C | Three-Way Match (Sales): ERP automatically reconciles Sales Order pricing, Shipped Quantity (DO), and Billed Quantity. Deviations outside 0% trigger a hard system hold. | P / A | Revenue Accounting | ERP Automated System Match Report |
REV-KC-04 | Cash Recs | Cash collections misappropriated, applied incorrectly, or diverted (lapping fraud). | C,E | Daily automated bank statement download is reconciled against the AR ledger. Unapplied cash is reviewed weekly by the Treasury Controller. | D / SA | Treasury Accountant | Monthly Bank Rec Statement with CFO Sign-off |
2. Procurement and Payment Cycle (Expenditure & Payables)
2.1 End-to-End Procedural Flow
Purchase Requisition (PR): Raised by originating department with budget codes.
Sourcing & Vendor Master Setup: Vendor onboarded via compliance background check; bank info locked in ERP.
Purchase Order (PO): Dispatched to vendor following financial threshold matrix approval.
Goods Receipt (GR): Receiving dock inspects physical condition and logs quantities against PO.
Invoice Verification (AP): Invoice received digitally, matched via systematic checks.
Payment Disbursement: Batch payment runs organized via treasury; dual token authorizations executed via corporate banking.
2.2 Process Flow Diagram
[PR Raised & Budget Check] ──> [Vendor Master Setup] ──> [PO Issued via Matrix]
│
[Dual Token Bank Run] <── [Payment Voucher] <── [Three-Way Match] <── [GRN Logged]2.3 Risk & Control Matrix (RCM)
Control ID | Process Step | Risk Description (What Could Go Wrong - WCGW) | Financial Assertion | Control Activity Description | Type / Mode | Owner | Evidence Artifact |
PRC-KC-01 | Vendor Master | Fictitious vendors created by internal staff to execute fraudulent payments. | E | Modification or creation of records in the Vendor Master File requires independent review by the Compliance Unit and dual-authorization workflow. | P / M | Master Data Team | Approved Vendor Onboarding Packet |
PRC-KC-02 | Order Processing | Purchasing commitments exceed approved corporate budgets, leading to unapproved expenditures. | A,P | ERP system validates funds availability against the cost-center budget before allowing PR-to-PO conversion. | P / A | Procurement Specialist | System Budget Availability Exception Report |
PRC-KC-03 | Processing | Payment generated for services or goods never delivered, or for incorrect rates. | E,A | Three-Way Match (Procurement): Payment vouchers cannot be processed unless a valid PO, verified Goods Receipt Note (GRN), and Supplier Invoice match. | P / A | Accounts Payable | System Verified Voucher Pack |
PRC-KC-04 | Disbursement | Unauthorized corporate fund outflows via malicious or incorrect bank transfers. | E | Electronic banking platform mandates dual-token authentication for all cash disbursements. Payments >$50,000 require CFO secondary approval. | P / SA | Treasury Director | Bank Settlement Log & Authorized Token Report |
3. Financial Reporting Cycle (General Ledger & Closing)
3.1 End-to-End Procedural Flow
Sub-ledger Close: AP, AR, Fixed Assets, and Payroll modules closed sequentially.
Journal Entry Preparation: Non-routine, accrual, and consolidation adjustments drafted with worksheets.
Review & Posting: Independent oversight checking allocation accuracy and accounting policies.
Account Reconciliations: Balance sheet accounts substantiated via underlying dynamic evidence.
Financial Consolidation: Eliminate intercompany transactions and convert currencies.
Disclosure & Disclosure Review: Drafting final statements, footnotes, and regulatory forms.
3.2 Process Flow Diagram
[Sub-Ledger Freeze] ──> [Journal Preparation] ──> [Independent Review & Post]
│
[Executive / Board Review] <── [Consolidation & Adjustments] <── [Balance Sheet Substantiation]
3.3 Risk & Control Matrix (RCM)
Control ID | Process Step | Risk Description (What Could Go Wrong - WCGW) | Financial Assertion | Control Activity Description | Type / Mode | Owner | Evidence Artifact |
FIN-KC-01 | Journal Ledger | Management overrides controls via fraudulent manual journal entries to distort metrics. | E,A | Manual journals require Segregation of Duties: Creator cannot post. All entries >$10,000 require automated workflow routing to the Financial Controller. | P / A | Accounting Manager | System Audit Log of Manual JVs |
FIN-KC-02 | Reconciliations | Balance Sheet accounts contain undetected material variances or unresolved reconciling items. | A | All key balance sheet accounts are reconciled to sub-ledgers or external sources monthly. Reconciliations are reviewed and signed off by the GL Director within 15 business days of close. | D / M | GL Director | Signed Reconciliation Dashboard |
FIN-KC-03 | Consolidation | Intercompany transactions fail to eliminate, leading to inflated revenues and assets. | A,P | The ERP consolidation engine performs automated intercompany matching and elimination. A manual variance review is executed by the Group Reporting Team. | D / SA | Group Reporting Manager | System Intercompany Elimination Report |
4. Investment Cycle (Treasury, M&A, & Securities)
4.1 End-to-End Procedural Flow
Sourcing & Allocation: Corporate development identifies targets or treasury assesses cash-equivalent instruments.
Financial Modeling & Due Diligence: Valuation stress-testing under dynamic assumptions (NPV, IRR).
Governance Clearance: Formally presented to the Investment/Board Committee.
Execution & Custody: Legal contracts signed; asset certificates registered or placed in secure institutional custody.
Impairment & Fair-Value Revaluation: Regular monitoring of carrying costs against market indexes.
4.2 Process Flow Diagram
[Pipeline / Treasury Sourcing] ──> [Due Diligence & Valuations] ──> [Board Committee Approval]
│
[Periodic Fair-Value Audit] <── [Asset Custody Controls] <── [Capital Wire & Settlement]
4.3 Risk & Control Matrix (RCM)
Control ID | Process Step | Risk Description (What Could Go Wrong - WCGW) | Financial Assertion | Control Activity Description | Type / Mode | Owner | Evidence Artifact |
INV-KC-01 | Governance | Company engages in high-risk, unauthorized investments, violating the board's risk appetite. | R,P | All investments exceeding $100,000 must align with the approved Corporate Investment Policy Statement (IPS) and receive written Board Investment Committee approval. | P / M | Board Secretary | Signed Board Minutes & Resolution |
INV-KC-02 | Custody | Securities or equity ownership certificates are lost, stolen, or misstated. | E | Independent physical/digital asset verification of certificates and portfolios is performed quarterly against external custodian statements. | D / M | Internal Audit | Custodian Confirmation Letters & Reconciliations |
INV-KC-03 | Revaluation | Changes in investment values are ignored, resulting in overstated asset values. | A | Semi-annual impairment assessments are performed for equity investments and long-term joint ventures. Valuation models use audited inputs or third-party reports. | D / M | CFO | Signed Impairment Review Memo |
5. Financing Cycle (Debt & Equity Capital Operations)
5.1 End-to-End Procedural Flow
Liquidity Planning: Long-range cash forecast identifies financing or equity raise requirements.
Negotiation: Institutional bidding for loan facilities, bonds, or private placements.
Statutory Approvals: Legal checks against maximum leverage ratios per bylaws.
Drawdown Administration: Tracking principal execution, interest schedules, and monitoring loan covenants.
Equity Cap Table Operations: Managing shares outstanding, option exercises, and dividend payments.
5.2 Process Flow Diagram
[Liquidity Forecast] ──> [Term Sheet Negotiation] ──> [Legal Matrix & Bylaw Validation]
│
[Cap Table & Covenant Tracking] <── [Interest / Principal Run] <── [Fund Execution & Ledgering]
5.3 Risk & Control Matrix (RCM)
Control ID | Process Step | Risk Description (What Could Go Wrong - WCGW) | Financial Assertion | Control Activity Description | Type / Mode | Owner | Evidence Artifact |
FIN-KC-04 | Compliance | Debt covenants are breached, triggering immediate default and loan acceleration. | P,A | A Covenant Compliance Dashboard tracks leverage/liquidity metrics monthly. The General Counsel reviews this prior to signing the compliance certificate. | D / SA | Treasury Manager | Quarterly Signed Compliance Certificate |
FIN-KC-05 | Equity Registry | Share issuance occurs without proper authorization, resulting in equity dilution or regulatory fines. | E,R | Changes to the capitalization table (options, equity awards) must be authorized by the Board Compensation Committee and confirmed by an external transfer agent. | P / M | Corporate Secretary | Transfer Agent Registry Report |
6. Construction Cycle (Capital Projects / CIP)
6.1 End-to-End Procedural Flow
Project Initiation: Business case and formal Capital Expenditure (CAPEX) authorization requested.
Engineering Tender: Competitive RFP issued to audited Engineering, Procurement, Construction (EPC) firms.
Construction-In-Progress (CIP) Accounting: Ongoing project expenditures aggregated into designated CIP general ledger clearing accounts.
Physical Progress Audit: On-site inspections evaluate milestone tracking before processing contractor billings.
Capitalization Run: Asset components separated and moved to active Fixed Asset Registers upon operational handover.
6.2 Process Flow Diagram
[CAPEX Charter & Budget] ──> [EPC Firm Competitive RFP] ──> [CIP Cost Aggregation Ledger]
│
[FAR Component Activation] <── [Handover Certificate] <── [Quantity Surveyor Progress Validation]
6.3 Risk & Control Matrix (RCM)
Control ID | Process Step | Risk Description (What Could Go Wrong - WCGW) | Financial Assertion | Control Activity Description | Type / Mode | Owner | Evidence Artifact |
CON-KC-01 | CAPEX Launch | Projects initiated without economic viability, leading to capital wastage. | E | Project charters require a documented NPV calculation and written sign-off from the CAPEX Review Committee prior to vendor commitments. | P / M | CAPEX Committee | Signed Project Charter & ROI Model |
CON-KC-02 | Progress Pay | Contractors bill for unearned milestones, causing overpayment and asset misstatement. | A | Milestone billings require an independent Quantity Surveyor's physical validation report and field project manager certification before invoice approval. | P / M | Project Director | Signed Progress Inspection Certificate |
CON-KC-03 | Capitalization | Finished assets remain in CIP accounts to defer depreciation, overstating net income. | P,A | Engineering provides formal Certificates of Substantial Completion monthly. Finance reconciles these to clear CIP accounts into the active Fixed Asset Register. | D / M | Fixed Asset Manager | Asset Capitalization Form (ACF) |
7. Fixed Assets Cycle (Property, Plant, & Equipment)
7.1 End-to-End Procedural Flow
Asset Activation: Barcode tagging and FAR profile configuration (useful life setting).
Depreciation Calculation: Run monthly based on systematic parameters (Straight Line, Reducing Balance).
Physical Verification: Tracking physical existence and conditions across geo-locations.
Asset Disposal/Scrapping: Formal decommission workflows assessing salvage book values.
7.2 Process Flow Diagram
[FAR Configuration & Tagging] ──> [Systematic Depreciation Run]
│
[Approved Asset Disposal] <── [Annual Physical Inventory Validation]
7.3 Risk & Control Matrix (RCM)
Control ID | Process Step | Risk Description (What Could Go Wrong - WCGW) | Financial Assertion | Control Activity Description | Type / Mode | Owner | Evidence Artifact |
AST-KC-01 | Asset Tracking | Fixed assets are stolen or misplaced without detection, overstating asset registers. | E | A wall-to-wall physical asset inventory is conducted annually by personnel independent of asset custody, reconciling items back to the FAR. | D / M | Internal Audit Lead | Reconciled Physical Inventory Report |
AST-KC-02 | Depreciation | Incorrect useful lives applied, resulting in misstated depreciation expenses and net book values. | A | Asset profiles are locked in the ERP by asset class. Modifications to configured useful lives require corporate accounting policy variance approval. | P / A | Fixed Asset Manager | ERP System Configuration Settings Log |
AST-KC-03 | Decommission | Assets are disposed of below book value without authorization or to favor internal staff. | E,A | Asset disposals require an approved Asset Disposal Form (ADF). Disposals of assets with net book values >$5,000 require CFO sign-off. | P / M | Operations VP | Executed ADF & Bill of Sale |
8. HR and Payroll Cycle
8.1 End-to-End Procedural Flow
Workforce Planning & New Hire Onboarding: Verified background screens, approved offer letters, and setting up core profiles in the HRIS (Workday/SAP SuccessFactors).
Time & Attendance Management: Submitting and digitally approving project/shift hours.
Payroll Calculation Engine: Running data aggregations (gross salary, social security withholdings, adjustments).
Disbursement Authorization: Reconciling variances against payroll templates prior to bank transmission.
Offboarding & Termination: Issuing final settlements, updating payroll registers, and revoking physical/logical system access.
8.2 Process Flow Diagram
[HRIS Setup & Compliance Check] ──> [Approved Time Sheets] ──> [Payroll Aggregation Run]
│
[System Access Deactivation] <── [Final Settlement] <── [Variance Check & Disbursement]
8.3 Risk & Control Matrix (RCM)
Control ID | Process Step | Risk Description (What Could Go Wrong - WCGW) | Financial Assertion | Control Activity Description | Type / Mode | Owner | Evidence Artifact |
PAY-KC-01 | New Hire Onboarding | Ghost employees added to the HRIS, leading to unauthorized cash outlays. | E | Creating an employee profile in the HRIS requires an electronic workflow attached to a signed employment agreement and verified tax documentation. | P / A | HR Operations Director | Audit Trail of HRIS User Creation |
PAY-KC-02 | Payroll Review | Incorrect payroll calculations or unauthorized bonus adjustments occur undetected. | A | Before bank file transmission, a Corporate Payroll Variance Report compares current and prior month runs. Variances >3% per individual must be verified. | D / SA | Finance Director | Signed Monthly Payroll Variance Review |
PAY-KC-03 | Offboarding | Terminated employees continue to receive salary payments post-departure. | E,A | HR enters termination into the HRIS within 24 hours of separation. This automatically removes the employee profile from the upcoming active payroll run. | P / A | HR Systems Lead | Automated Termination Log vs Payroll Export |
9. IT General Controls Cycle (ITGC Framework)
9.1 End-to-End Procedural Flow
Logical Access Governance: Enforcing access controls through multi-factor authentication (MFA) and single sign-on (SSO).
Change Management Administration: Structuring code/infrastructure changes via Sandbox → Staging → Production.
IT Operations & Cyber Defense: Managing system monitoring, daily backups, and disaster recovery execution plans.
9.2 Process Flow Diagram
[Access Provisioning & RBAC] ──> [Sandbox Code Review] ──> [Staging Testing & Approval]
│
[Disaster Recovery Drills] <── [Immutable Backup Runs] <── [Production Deployment Engine]
9.3 Risk & Control Matrix (RCM)
Control ID | Process Step | Risk Description (What Could Go Wrong - WCGW) | Financial Assertion | Control Activity Description | Type / Mode | Owner | Evidence Artifact |
ITG-KC-01 | Access Control | Excessive system privileges lead to unauthorized data modifications or Segregation of Duties violations. | All Assertions | Privilege management follows Role-Based Access Control (RBAC). Access rights are reviewed quarterly by department heads to confirm access remains appropriate. | D / M | IT Security Manager | Quarterly User Access Review Sign-offs |
ITG-KC-02 | Change Management | Unapproved or untested code updates disrupt ERP financial processing logic. | A | Changes to production environments require a documented ticket detailing testing in a staging environment and explicit Change Advisory Board (CAB) approval. | P / SA | Change Management Chair | Closed CAB Deployment Ticket |
ITG-KC-03 | Operations | Ransomware or system failures lead to data loss or unrecoverable financial ledgers. | C,A | Automated full backups are performed daily and stored in an immutable, off-site cloud environment. Recovery tests are completed and documented semi-annually. | P / A | Infrastructure Director | Semi-Annual Backup Restoration Test Log |
SECTION III: APPENDIX – PROFESSIONAL TEMPLATES & FORMS
To build out the auxiliary sections of the manual, use the standardized operating blueprints below.
1. Template: Credit Evaluation and Limit Approval Form
FORM CODE: FIN-CR-001A
================================================================================
CUSTOMER IDENTIFICATION
Customer Name: ________________________ Registration No: _____________________
Country of Incorporation: _____________ Tax Identification ID: ______________
FINANCIAL METRICS ASSESSMENT (FY-2026/LTM)
Annual Revenue: $_____________________ Net Current Assets: $__________________
Leverage Ratio (Debt/Equity): ________ Altman Z-Score Calculation: __________
PROPOSED CREDIT TERMS
Requested Limit: $____________________ Requested Payment Window: ______ Days
Internal Credit Rating Assigned: [ ] Low Risk [ ] Medium Risk [ ] High Risk
APPROVAL WORKFLOW
Credit Risk Analyst Signature: _______________________ Date: 2026-__-__
Credit Director Approval (> $50k): _____________________ Date: 2026-__-__
CFO Secondary Validation (> $250k): __________________ Date: 2026-__-__
================================================================================
2. Template: Capital Expenditure (CAPEX) Project Charter Form
FORM CODE: CPX-PC-007B
================================================================================
PROJECT OVERVIEW
Project Title: _________________________________________________________________
Originating Asset/Site Location: _______________________ Cost Center: _________
Target Operational Date: 2026-__-__
FINANCIAL FEASIBILITY ANALYSIS (Attach Detailed Spreadsheet)
Total Estimated Capital Budget: $_______________________
Expected Payback Period: ______________ Months
Calculated Net Present Value (NPV): $__________________ (Discount Rate Used: __%)
Internal Rate of Return (IRR): ________%
COMPLIANCE STRATEGY & TESTING MANDATES
Does this procurement interface with automated financial reporting tools? [Yes/No]
List corresponding control IDs managed by this asset deployment: _____________
MANAGEMENT AUTHORIZATION
Department VP Authorization: _________________________ Date: 2026-__-__
CAPEX Committee Validation: __________________________ Date: 2026-__-__
Executive Board Resolution ID (If >$1M): _______________ Date: 2026-__-__
================================================================================
3. Template: Access Provisioning & Segregation of Duties (SoD) Clearance Form
FORM CODE: IT-SOD-003C
================================================================================
USER IDENTIFICATION & SYSTEM PROFILE
Full Legal Employee Name: ___________________________ Employee ID: ___________
Department: _________________________________________ Job Title: ______________
Target Enterprise System: [ ] SAP S/4HANA [ ] Oracle Cloud [ ] Workday [ ] Other
REQUESTED SYSTEM PROFILES/ROLES
Role Code 1: ________________________ Description: ___________________________
Role Code 2: ________________________ Description: ___________________________
SEGREGATION OF DUTIES (SOD) CONFLICT VERIFICATION MATRIX
Check potential conflict pairs:
[ ] AP Voucher Creation + Bank Payment File Generation [CONFLICT DETECTED]
[ ] Customer Master Setup + Sales Invoice Issuance [CONFLICT DETECTED]
[ ] Journal Voucher Creation + General Ledger Posting [CONFLICT DETECTED]
Risk Assessment Findings:
[ ] Zero conflicting matrices identified under requested application profiles.
[ ] Conflict detected. Compensating Control Matrix ID linked: _________________
SIGN-OFF CLEARANCE
Requesting Manager Signature: ________________________ Date: 2026-__-__
Risk & Compliance Auditor Validation: ________________ Date: 2026-__-__
CIO Infrastructure Authorization: ____________________ Date: 2026-__-__
================================================================================
SECTION IV: EXECUTION GUIDELINES FOR THE 400+ PAGE VOLUME
To scale this foundational blueprint to a comprehensive manual for organizational rollout:
Populate Business Unit Variances: Expand the sub-ledger sections to document specific workflows for local operating models (e.g., subscription billings vs. physical product inventory lines).
Incorporate Detailed System Walkthroughs: Embed step-by-step transaction pathways into the procedures (e.g., detailing exactly which transaction codes or system menus to use when running a three-way match report or executing a bank run).
Expand Risk Scenarios: Build out the Risk and Control Matrix to cover edge cases, such as handling split-shipments or mid-month contract amendments, ensuring each scenario is mapped to a documented control activity and testing procedure.
Resources: Internet
Comments